Your customer is asking for AI Act documentation
It usually arrives as one line in a procurement thread — “before we can proceed, can you send your AI Act documentation?” — and the deal stops there. Not because anyone is being difficult, but because your buyer has duties it cannot discharge with a product demo.
This page is the vendor side of that conversation: the 12 things buyers actually ask for, the provision each one comes from, and what to send back. No article on this page is invented, and every date resolves from the same deadline table the rest of the site runs on.
Six questions, no sign-up — you get the documents that apply to you, the ones that do not and why, and a PDF you can forward to the buyer.
What binds you today, and what does not
Being precise here is worth money, because the honest answer is more useful than the alarming one. One row below is enforceable against you right now. The heavy ones are not — and your buyer is asking about them anyway.
- In force since 2 August 2026In force
Enforceable today. It binds you whether or not anything you sell is high-risk.
- In force since 2 August 2025In force
Enforceable today, on the model provider above you — which is why the material you need to answer already exists.
- Applies from 2 December 2027Upcoming
Not enforceable against your buyer yet. They are asking anyway, because they are deciding now whether they can adopt you at all.
- Applies from 2 August 2028Upcoming
The separate track for AI inside regulated products — medical devices, machinery, toys, vehicles.
- Commercial, not statutory
No article requires this. It is the buyer's own diligence, and it is what actually holds up signatures.
The high-risk dates moved: the 2026 Digital Omnibus pushed Annex III obligations to 2 December 2027 and the Annex I product track to 2 August 2028. Article 50 was not moved. See the deadline tracker for every milestone.
Why the ask arrives years before the deadline
Your buyer may become the provider
A deployer, importer or distributor that puts its own name or trademark on a high-risk system, substantially modifies it, or repurposes it into a high-risk use is treated as the provider — inheriting the full Article 16 duty set, including a fresh conformity assessment. Anyone white-labelling you is reading that sentence carefully.
Deployer duties do not transfer to you
Human oversight, use in line with your instructions, monitoring, log retention, informing workers and affected people — these are the buyer’s own obligations. Several of them are impossible to meet without documents only you can write, which is how a legal duty becomes your inbox.
And this one is already live
If your product talks to people or generates content, the transparency duties bind you now, independently of anything the buyer does. Disclosure that the user is dealing with AI, machine-readable marking of generated output, a visible label on deepfakes.
What your customer will actually ask for
Not all of these are yours — answer six questions and get only the rows that apply to you, plus a forwardable PDF.
Each row is one question a buyer sends, the document that answers it, the provision the question comes from, and how to produce it. Where a row is procurement habit rather than law, it says so.
- 1Art. 3(3), Art. 3(4), Art. 25In force since 2 August 2026
“For this system, are you the provider and are we the deployer? Put it in writing.”
- Send them
- A written role statement naming who is the provider and who is the deployer for this deployment, and what happens if the buyer rebrands or modifies it.
- Where it comes from
- The Act assigns duties by operator role, not by contract. Article 25 makes a deployer, importer or distributor the provider of a high-risk system the moment it puts its own name or trademark on it, substantially modifies it, or repurposes it into a high-risk use — so a white-label buyer is asking you a question it genuinely cannot answer alone. Read Art. 3(3), Art. 3(4), Art. 25
- In Conformly
- Classifies each system deterministically and names the role and the articles behind the answer, so the statement you sign is derived rather than asserted. Free classifier
- 2Art. 11 + Annex IVApplies from 2 December 2027
“Send us your technical documentation for this system.”
- Send them
- The Annex IV technical file: description, development process, monitoring, risk management, changes and standards applied.
- Where it comes from
- Providers of high-risk systems must draw the technical documentation up before the system is placed on the market and keep it current; Annex IV lists the required contents. Microenterprises and small companies may use a simplified form. Read Art. 11 + Annex IV
- In Conformly
- Walks the Annex IV sections in order and exports the completed technical file as Markdown and PDF. Annex IV generator
- 3Art. 43, Art. 47, Art. 48Applies from 2 December 2027
“Do you have an EU declaration of conformity, and is the system CE marked?”
- Send them
- The written EU declaration of conformity, naming the system and the standards applied.
- Where it comes from
- The provider passes a conformity assessment — internal control for most Annex III systems, a notified body in specific cases — then draws up the declaration and affixes the CE marking. The declaration is kept for ten years and produced to authorities on request. A substantial modification triggers a fresh assessment. Read Art. 43, Art. 47, Art. 48
- In Conformly
- Generates the declaration of conformity and the other per-system deep documents from the record you already maintain. Compliance documents
- 4Art. 13, with Art. 26(1)Applies from 2 December 2027
“Send us the instructions for use — our team needs to know how to run this correctly.”
- Send them
- Instructions for use covering intended purpose, capabilities, limitations and the conditions the system must be operated under.
- Where it comes from
- Providers must supply instructions clear enough that deployers can meet their own obligations — and Article 26(1) requires the deployer to use the system in line with exactly those instructions. Without your document your customer is structurally unable to comply, which is why procurement stops here. Read Art. 13, with Art. 26(1)
- In Conformly
- Holds the per-system instruction set alongside the rest of the file, so the version you ship and the version you documented are the same one. Compliance documents
- 5Art. 10Applies from 2 December 2027
“What was this trained on, and how do you check it for bias?”
- Send them
- A data-governance note: provenance, collection and preparation, representativeness, and how bias is examined for and mitigated.
- Where it comes from
- Training, validation and test data for high-risk systems must be relevant, sufficiently representative and, as far as possible, error-free, under documented governance covering the whole data lifecycle — including examination for biases likely to affect health, safety or fundamental rights. Read Art. 10
- In Conformly
- The development-process section captures data requirements, provenance and training methodology in the same file the technical documentation comes from. Annex IV generator
- 6Art. 14, with Art. 26(2)Applies from 2 December 2027
“What can our people actually do when it gets something wrong?”
- Send them
- A description of the built-in oversight measures, plus the operating instruction the buyer's staff will follow to intervene, override or stop the system.
- Where it comes from
- The provider designs oversight so a person can understand the system's limits, interpret its output correctly, override it and halt it; the deployer operationalises that by assigning competent people with the authority to act. Your customer is being asked to name those people and needs your design to do it. Read Art. 14, with Art. 26(2)
- In Conformly
- Turns the classification into the concrete obligation list, so the oversight measure is a tracked item with evidence attached rather than a paragraph in a PDF. Obligations tracker
- 7Art. 50(1), (2), (4)In force since 2 August 2026
“Where does your product tell people they are talking to AI, and how is generated content marked?”
- Send them
- The disclosure text your interface shows, the machine-readable marking configuration for generated output, and the visible label on any deepfake content.
- Where it comes from
- Systems that interact directly with people must inform them they are interacting with AI unless that is obvious; synthetic audio, image, video and text must be marked machine-readably as artificially generated; deepfakes carry a visible disclosure on top. This is the one on the list that is already enforceable, and it binds you whether or not anything you sell is high-risk. Read Art. 50(1), (2), (4)
- In Conformly
- The free checker tests your current disclosures; in-product, each system gets a hosted disclosure page and a one-line embed chip you drop into the interface. Disclosure page + embed chip
- 8Art. 53(1)(b)In force since 2 August 2025
“Which model is behind this feature, and what did its provider give you?”
- Send them
- The model inventory for your product, with the downstream-provider information you received from each model provider passed on to your buyer.
- Where it comes from
- Providers of general-purpose AI models must give downstream providers the information and documentation they need to comply with the Act. Those duties have applied since the GPAI date below, so the material you need to answer this exists — the work is knowing which model sits behind which feature and holding the paperwork you were given. Read Art. 53(1)(b)
- In Conformly
- Records each AI vendor and model you depend on with the documentation and answers you collected; the public directory pre-fills the due-diligence questions to send. Vendor register
- 9Art. 73Applies from 2 December 2027
“If this causes harm, when and how do you tell us?”
- Send them
- A written incident process naming your notification route and the clock you run to.
- Where it comes from
- Providers of high-risk systems report serious incidents to the market-surveillance authority immediately after establishing a causal link and no later than the set deadlines — generally 15 days, 10 where a death is involved, and as little as 2 days for a widespread infringement or critical-infrastructure disruption. Deployers must alert the provider on becoming aware, which is precisely why your customer wants the route documented before it signs. Read Art. 73
- In Conformly
- Logs incidents against the Art. 73 categories and tracks each one on its own 2 / 10 / 15-day reporting clock. Incident log
- 10Art. 72Applies from 2 December 2027
“How do you watch this after it ships — and what would make you pull it?”
- Send them
- A post-market monitoring plan: what real-world performance data you collect, how it is reviewed, and what triggers corrective action.
- Where it comes from
- Providers of high-risk systems must run a documented, plan-based monitoring system proportionate to the risk, collecting and analysing performance data across the system's life and feeding it back into risk management under Article 9. Read Art. 72
- In Conformly
- Runs the continuous checks and keeps the record that shows the plan is being executed rather than merely written. Monitoring
- 11Art. 6(1), Annex IApplies from 2 August 2028
“Our product is CE marked already. Does your AI component change our conformity assessment?”
- Send them
- A statement of whether your component is a safety component of the buyer's regulated product, and what your documentation contributes to their existing assessment.
- Where it comes from
- A system is also high-risk when it is a safety component of a product covered by the EU harmonisation legislation listed in Annex I and that product requires third-party conformity assessment. If you sell into medical devices, machinery, toys or vehicles, this is the track your buyer is on — and it runs on its own date. Read Art. 6(1), Annex I
- In Conformly
- Separates the Annex I product-safety route from the Annex III use-case route and shows which one your system lands on, with the reasoning. Free classifier
- 12Not an Act artefactCommercial, not statutory
“Complete our AI vendor assessment questionnaire — sixty questions, by Friday.”
- Send them
- A reusable answer set drawn from your own approved policies, controls and evidence, plus a public page the next buyer can read without asking.
- Where it comes from
- No article requires a vendor questionnaire or a trust page. They exist because buyers with duties under Articles 25, 26 and 50 have to evidence their own diligence, and asking you is the cheapest way to do it. Treat this row as commercial reality, not law — but it is the row that actually holds up signatures.
- In Conformly
- Drafts each answer from evidence you have already approved — never invented — and the Trust Center publishes the stable parts so the tenth buyer reads instead of emails. Questionnaires + Trust Center
First settle which role you are
Nothing on the checklist above can be answered until this is fixed, because the Act assigns duties by operator role rather than by contract. Most AI vendors are providers, some are deployers of somebody else’s model inside their own product, and a good number are both at once.
You are the provider if…
you develop the system, or have it developed, and place it on the EU market or put it into service under your own name or trademark — whether you charge for it or give it away. Location is irrelevant: if the output is used in the EU, you are in scope, and a provider established outside the Union additionally needs an EU authorised representative under Article 22.
You are also a deployer if…
you use an AI system under your own authority in your professional activity — which includes the third-party model sitting inside your own product. The two roles stack rather than substitute, so the GPAI provider’s documentation does not discharge your duties, and yours do not discharge your customer’s.
The white-label trap
If your customer resells your system under its own brand, Article 25 makes them the provider of it — with a conformity assessment to run and a technical file to hold. They will only agree to that if you can hand over the evidence underneath it. This is the single most common reason a white-label deal stalls at legal review.
This is a sales accelerator, not a compliance cost
The work on the checklist happens either way. The only variable is whether it happens before the deal or during it — and doing it during is what turns a two-week legal review into a quarter. A vendor who answers with a document instead of a meeting takes itself off the buyer’s critical path.
Answer once, not per prospect
Inbound AI and security questionnaires get drafted from evidence you have already approved, rather than reconstructed from memory by whoever is free that week.
QuestionnairesPublish the stable parts
A Trust Center gives buyers a link instead of a thread — your systems, their classification and your posture, readable before anyone books a call.
Trust CenterKnow your own supply chain
You cannot answer “which model is behind this?” without a register of the vendors and models you depend on, and the documentation each of them gave you.
AI vendor directoryFrequently asked questions
Our customer is asking for AI Act documentation, but the high-risk rules do not apply until 2027. Can we wait?
You can wait on the obligation and still lose the deal. The Annex III high-risk duties are not enforceable against your customer yet, but the customer is deciding today whether it can adopt you at all — and under Article 25 it may become the provider of your system the moment it rebrands or substantially modifies it. Procurement stops at the point where the buyer cannot describe the system it is buying, and that point has already arrived.
Which of these asks is legally binding on us right now?
The Article 50 transparency duties. Systems that interact with people must disclose that they are AI unless it is obvious, synthetic audio, image, video and text must be marked machine-readably, and deepfakes carry a visible label. That applies whether or not anything you sell is high-risk, and it has applied since 2 August 2026. The GPAI model-provider duties in Articles 53 to 55 have applied since 2 August 2025, which is what makes model documentation available for you to pass on.
We only sell the software. Is compliance not the customer's problem?
The duties split, they do not transfer. If you develop the system and place it on the market under your own name you are the provider, with the Article 16 duty set. Your customer is the deployer, with independent Article 26 duties — human oversight, use per your instructions, monitoring, logs, informing affected people. Several of those duties are impossible to meet without documents only you can produce, which is exactly why the request lands with you.
Our customer white-labels our product. What changes?
Article 25 changes it. A deployer, importer or distributor that puts its own name or trademark on a high-risk system, substantially modifies it, or repurposes it into a high-risk use is treated as the provider of that system and inherits the Article 16 obligations, including a fresh conformity assessment. Buyers who understand this ask harder questions before signing, and buyers who do not will ask them after — usually during an audit.
Is a trust page or a completed questionnaire required by the AI Act?
No. Neither is an Act artefact, and this page marks them as commercial rather than statutory. They matter because the buyer has real duties and needs evidence of diligence, and answering the same sixty questions for every prospect is the part of the sales cycle that silently costs you weeks.
We sell an AI component that goes inside a CE-marked product. Which deadline applies to us?
The Annex I product-safety track, which runs to 2 August 2028 rather than the 2 December 2027 Annex III date. A system is high-risk on that route when it is a safety component of a product covered by the EU harmonisation legislation in Annex I and that product needs third-party conformity assessment. Your buyer is fitting your documentation into an assessment it already runs, so the earlier you can state what your component is, the less friction there is.
What does it cost us to be the vendor that already has this ready?
Less than the alternative, because the work is the same work either way — the only variable is whether it happens before the deal or during it. A vendor that answers with a document instead of a meeting removes itself from the buyer's critical path, and the buyer's legal review stops being a reason the quarter slips.
The free checker classifies each system deterministically, names your role, and shows the articles behind every answer — which is the first line of every document above. No sign-up.
This page summarises Regulation (EU) 2024/1689 as amended by the 2026 Digital Omnibus on AI. It is general information, not legal advice, and what any given provision requires of you depends on the system you sell and the role you hold.